RedScore.ai

Free port scanner

See public exposure risk on your domain before attackers do

RedScore checks what the internet can already see on your live hostname.

People search for a port scanner when they want to know what is exposed. RedScore runs a passive outside-in scan in about 60 seconds and ranks public exposure signals with your full RedScore. No signup and no invasive probing on the free scan.

Scan your domain

Free scan · No signup · Results in ~60 seconds · Opens /lookup

example-corp.com

✓ scan complete · grade D · 4 issues

42/ 100
Grade D

AI summary

DMARC enforcement is missing, which leaves spoofing open. SPF is too permissive. Several key web security headers are absent.

FAILDMARC enforcement
FAILSPF policy strength
WARNWeb headers & TLS hardening
WARNCookie secure flag
PASSGoogle Safe Browsing

Why exposure checks matter

Open services are one of the first things strangers check

Buyers, insurers, and opportunistic scanners look for public exposure before they ever talk to your team. RedScore gives you the outside-in view so you can close obvious gaps before a review or incident.

Built for fast answers

Exposure posture, not a noisy port sweep

Go to /lookup, enter your domain, and get graded exposure signals plus nine other public security areas.

Outside-in exposure check

RedScore reads public exposure indicators visible from the internet on your domain.

Fix-first ranking

See which public gaps matter most without opening five different security tabs.

Safe on production

Passive scan only. No exploit attempts and no credentials required.

Claim for full detail

Domain owners can claim the site to unlock complete findings and monitoring.

What you get

Exposure grades inside a full RedScore

You get a 0-100 score, letter grades across ten public security areas, and a short summary that includes exposure posture alongside DNS, email, headers, and TLS.

C62DNS & Domain Security
D48Email Security
B75Infrastructure Hygiene
C68Web Application Security
F32Cookie & Privacy Hygiene
D45Technology Fingerprinting
B78Public Exposure
A91Certificate & PKI Health
B82Brand & Domain Reputation
C55Third-Party Risk Surface
63/ 100
Grade C

63 / 100

Grade C

example-corp.com

AI summary

Cookie settings are weak and server headers reveal stack details. Email spoofing is plausible with incomplete SPF and DMARC.

Email auth gaps
Header hardening
Certificate hygiene

What RedScore checks today

Public exposure signals on your domain

  • Public exposure indicators visible from the outside
  • TLS and certificate health on your live hostname
  • Security headers on deployed responses
  • DNS hygiene and delegation consistency
  • Reputation and blocklist signals where available

What this does not replace

This is not an invasive port sweep, authenticated pentest, or exploit scan. The free scan shows safe summary grades. Claim your domain to unlock detailed exposure findings.

After the free scan

Claim your domain for complete exposure findings

Anonymous scans show category grades and safe summaries. Claim the domain to see full exposure detail, schedule rescans, and get alerts when posture changes.

  • Full exposure and finding detail for verified owners
  • Scheduled scans and change alerts
  • Trust pages and PDF reports for stakeholder reviews

FAQ

Common questions

Check public exposure on your domain

Free scan · No signup · ~60 seconds

Scan your domain